Unauthorized parties gained access to names, addresses and CPR numbers belonging to around 8.8 million people registered in Denmark’s civil registration system, in what a cybersecurity professor calls the largest breach ever against the CPR register.
The breach was made public on October 5, 2026, and is reported by DR. Jens Myrup Pedersen, professor of cybersecurity at Aalborg University, told DR’s radio program P1 Morgen that there is no doubt this is the biggest breach ever against the Danish CPR register.
According to DR, the unauthorized access did not come from a direct attack on the register itself. The access was obtained through a private company that has a lawful right to make lookups in the CPR system. The Ministry of Research, Education and Digitalisation became aware of the incident over the weekend.
DR reports that the CPR administration has shut down the company’s access and reported the incident to Datatilsynet, the Danish Data Protection Authority. People registered with name and address protection were not included in the exposed data. TV 2 adds that the case was discovered after irregular behavior was observed in the CPR system during September 2026.
Why CPR numbers plus addresses make this case different
Pedersen told DR he looked into earlier security failures in the register after the news broke. In 2015, CD-ROMs containing CPR numbers were mistakenly sent to a Chinese company. Those discs did not contain address information, he noted, while this case does.
Per the professor, the combination of CPR numbers and addresses is what makes the breach so extensive. He said the era in which Danes could assume that others do not know their CPR number must now be over. As stated by Pedersen, it is a problem that citizens’ data is not better protected.
He also described how the data can be used. With names, addresses and CPR numbers, attackers can make phishing emails and text messages look official by referring to details only authorities would normally know. The same data can be used to impersonate people for identity theft, or be sold on to others.
Pedersen told DR that the rule of thumb for the register should be that no one has access to more data than they need. There should also be mechanisms that trigger alarms or blocks when an unusual number of lookups is made, he said. He added that compromising someone who already has access can be easier than forcing entry directly.
Much remains unclear. DR reports that little is known about how the unauthorized access took place, and even less about who is behind it. TV 2 states that the identity of those responsible and the full scope of the incident were not known on October 5, 2026.
What the CPR breach means for foreign residents in Denmark
The CPR register, the Civil Registration System, covers everyone who has been assigned a Danish personal identification number. Internationals receive a CPR number when they register a Danish address, usually after arriving on a residence or work permit or under EU rules. The number is used for everything from doctor visits and tax records to opening a bank account.
The 8.8 million affected records include people currently living in Denmark, people who have died, and people who have moved out of the country, according to DR. The CPR system contains around 11 million people in total. That means long-term foreign residents, former residents who have left Denmark, and newly arrived internationals can all fall within the affected group.
DR reports that names and addresses of people registered with name and address protection were not part of the exposed data. That protection, known in Danish as navne- og adressebeskyttelse, is registered through the municipality. What is not yet known is who obtained the data, how it was taken, or how it may be used, and Datatilsynet’s handling of the report was still in its early stages on October 5, 2026.






